Bugzilla – Bug 1234718
VUL-0: CVE-2024-11614: dpdk: Denial Of Service from malicious guest on hypervisors using DPDK Vhost library
Last modified: 2026-01-15 08:34:16 UTC
An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-11614 https://seclists.org/oss-sec/2024/q4/156 https://git.dpdk.org/dpdk-stable/commit/?id=fdf13ea6fede07538fbe5e2a46fa6d4b2368fa81 https://git.dpdk.org/dpdk-stable/commit/?id=e9c0ad133242c0bcb7801d2590e8bb5f7ac4ebfd https://git.dpdk.org/dpdk/commit/?id=4dc4e33ffa108e945fc8a1e2bbc7819791faa61e https://git.dpdk.org/dpdk-stable/commit/?id=1570aef08bfde179449a9501bd54888a7d5f2cd6 https://git.dpdk.org/dpdk-stable/commit/?id=b8e7797c11e5121d738b8c468ee08f3411474d1c https://bugzilla.redhat.com/show_bug.cgi?id=2327955 https://www.cve.org/CVERecord?id=CVE-2024-11614 https://access.redhat.com/security/cve/CVE-2024-11614 http://www.openwall.com/lists/oss-security/2024/12/17/3 https://github.com/CVEProject/cvelistV5/blob/main//cves/2024/11xxx/CVE-2024-11614.json
SUSE-SU-2025:0018-1: An update that solves one vulnerability can now be installed. URL: https://www.suse.com/support/update/announcement/2025/suse-su-20250018-1 Category: security (important) Bug References: 1234718 CVE References: CVE-2024-11614 Maintenance Incident: [SUSE:Maintenance:36878](https://smelt.suse.de/incident/36878/) Sources used: Server Applications Module 15-SP6 (src): dpdk-22.11.1-150600.3.9.1, dpdk-thunderx-22.11.1-150600.3.9.1 openSUSE Leap 15.6 (src): dpdk-22.11.1-150600.3.9.1, dpdk-thunderx-22.11.1-150600.3.9.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2026:20055-1: An update that solves two vulnerabilities and has one fix can now be installed. URL: https://www.suse.com/support/update/announcement/2026/suse-su-202620055-1 Category: security (moderate) Bug References: 1214724, 1234718, 1254161 CVE References: CVE-2024-11614, CVE-2025-23259 Sources used: SUSE Linux Micro 6.1 (src): dpdk-22.11.10-slfo.1.1_1.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2026:20036-1: An update that solves two vulnerabilities and has one fix can now be installed. URL: https://www.suse.com/support/update/announcement/2026/suse-su-202620036-1 Category: security (moderate) Bug References: 1214724, 1234718, 1254161 CVE References: CVE-2024-11614, CVE-2025-23259 Sources used: SUSE Linux Micro 6.0 (src): dpdk-22.11.10-1.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.